apify-ecommerce
Pass
Audited by Gen Agent Trust Hub on May 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the agent to execute a local Node.js script (
reference/scripts/run_actor.js) to initiate scraping tasks and process results. - [EXTERNAL_DOWNLOADS]: The skill's script fetches data and sends configuration to Apify's official API (
api.apify.com), which is a well-known service for web scraping and automation. - [CREDENTIALS_UNSAFE]: The skill correctly instructs users to store the
APIFY_TOKENin a local.envfile (~/.claude/.env) rather than hardcoding it, which is the recommended practice for secret management. - [DATA_EXFILTRATION]: While the skill processes data from external e-commerce marketplaces (Amazon, Walmart, etc.), it does so for the primary purpose of pricing intelligence and market research as described in the documentation. No unauthorized data movement was detected.
Audit Metadata